Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    azure activity logs threat analysis

    1

    Analyze Azure logs, build KQL hunting queries, and generate SOC-ready threat reports for cloud environments.

    $15

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    azure activity logs threat analysis

    azure activity logs threat analysis

    Example session with this skill installed

    Analyze these AzureActivity log exports from the last 24 hours. I suspect unauthorized privilege escalation in the production subscription. Provide a hunting report and KQL for validation.

    • Read your context and instructions
    • Compiled the azure activity logs
    • Generated the document

    I have analyzed the provided AzureActivity logs for the production subscription over the last 24 hours. The analysis focused on administrative role assignments and high-impact control plane changes.

    Azure Activity Log Threat Analysis Report

    FindingEvidence / OperationActorImpactConfidence
    Suspicious Role AssignmentMicrosoft.Authorization/roleAssignments/writesvc_deploy@contoso.comOwner permissions granted to a new service principal.High
    MFA Requirement BypassUpdate user (conditional access modification)admin_hunter@contoso.comReduced security posture for privileged accounts.Medium
    Key Vault Access ChangeMicrosoft.KeyVault/vaults/accessPolicies/writesvc_deploy@contoso.comPotential secret exfiltration capability.High

    Validation KQL Queries

    // Search for new Owner or Contributor assignments in the last 24 hours
    AzureActivity
    
    | where TimeGenerated > ago(24h)
    | where OperationNameValue == "Microsoft.Authorization/roleAssignments/write"
    | extend Properties_d = parse_json(Properties)
    | extend RoleDefinition = tostring(Properties_d.roleDefinitionId)
    | where RoleDefinition contains "8e3af657-a8ff-443c-a75c-2fe8c4bcb635" // Owner Role
    | project TimeGenerated, Caller, RoleDefinition, ResourceGroup, _ResourceId
    
    

    Detection Gaps

    • Gap: No active alert for 'Owner' role assignments outside of known PIM windows.
    • Gap: Lack of correlation between Service Principal creation and immediate permission assignment.

    Next steps

    1. Verify if svc_deploy@contoso.com was part of a scheduled deployment.
    2. Review the audit logs for admin_hunter@contoso.com to check for session hijacking signs.
    3. Implement the provided KQL as a scheduled analytic rule in Microsoft Sentinel.

    azure-activity-logs-threat-analysis.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Generate KQL hunting queries for Azure Activity and Entra ID logs.Triage suspicious cloud administrative activity during incident response.Document detection gaps for Azure control plane and identity events.Produce structured threat hunting reports for SOC and security leadership.

    About this skill

    The problem

    Security teams often struggle to parse through massive volumes of Azure Activity and Entra ID logs during incidents. Manually writing complex KQL queries while under pressure leads to missed indicators of compromise or inaccurate threat assessments.

    What it does

    • Generates KQL threat hunting queries for Azure control plane, identity, and Key Vault activity.
    • Analyzes provided log exports to identify suspicious administrative changes and privilege escalation attempts.
    • Produces structured threat hunting reports and incident support summaries based on evidence.
    • Maps findings to MITRE ATT&CK techniques and identifies detection gaps in current monitoring.
    • Converts log analysis into tool-agnostic detection logic or platform-specific SIEM content.

    Frameworks & tools

    Azure Activity Logs, Microsoft Entra ID (Azure AD), Kusto Query Language (KQL), Azure Log Analytics, and Azure Monitor.

    Why this beats prompting it yourself

    Standard LLM prompts often hallucinate KQL schemas or suggest offensive techniques. This skill enforces defensive boundaries, ensures schema accuracy for specific tables like SigninLogs or AzureDiagnostics, and follows a structured SOC-ready reporting methodology that separates facts from hypotheses.

    Use cases

    • Investigating a suspected credential theft via Entra ID sign-in anomaly logs.
    • Building a detection gap register for a new Azure subscription deployment.
    • Creating a timeline of administrative operations during a cloud security audit.
    • Developing custom KQL alerts for unauthorized Network Security Group changes.

    Known limitations

    Requires authorized log data or specific workspace context to be useful. Does not perform live tenant interrogation without pre-configured access and credentials.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 month ago

    • Passed all security checks, Safe to install

    Listed1 month ago

    What's inside

    Frequently Asked Questions